Daily Digest

Microsoft Patches Actively Exploited SharePoint Zero-Day in Massive Update, as Critical Flaws in Nginx-UI and Axios Emerge

Microsoft Patches Actively Exploited SharePoint Zero-Day in Massive Update, as Critical Flaws in Nginx-UI and Axios Emerge

April 16, 2026
11 articles (8 new, 3 updated)
33 min read

Summary

This cybersecurity brief for April 16, 2026, covers a massive Microsoft Patch Tuesday that addressed 165 flaws, including an actively exploited SharePoint zero-day (CVE-2026-32201). Concurrently, NIST announced a major overhaul of its NVD program, no longer enriching all CVEs due to overwhelming volume. Critical, actively exploited vulnerabilities were also disclosed in the popular Nginx-UI tool (CVE-2026-33032) and the Axios JavaScript library (CVE-2026-40175), posing significant risks of server takeover and cloud compromise. Ransomware and data breach activity remains high, with incidents reported at Autovista, Bank3, and Booking.com, alongside new threat campaigns targeting finance professionals via the Obsidian app.

Filter by Category

New Articles (8)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.